Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Canceled Signing event #1438

Closed
wants to merge 1 commit into from
Closed

Canceled Signing event #1438

wants to merge 1 commit into from

Conversation

sigstore-bot
Copy link
Member

Processing signing event sign/root-v12, please wait.

Simple version & expiry  bump

Signed-off-by: Jussi Kukkonen <[email protected]>
@sigstore-bot
Copy link
Member Author

Current signing event state

Event sign/root-v12 (commit c40ad4b)

❌ root

Role root is unsigned and not yet verified
Still missing signatures from @mnm678, @SantiagoTorres, @joshuagl, @dlorenc, @bobcallaway
Signers can sign these changes by running tuf-on-ci-sign sign/root-v12

@jku
Copy link
Member

jku commented Feb 5, 2025

This signing event is still in progress, please do not sign yet: We will notify
here and in slack channel when this is ready for signing.

  • First commit is a simple version bump: this should fail the signing event
    because we now have a check for the keyid issue (the reason for this signing
    event)
  • Second commit includes the keyid correction

Note that the result looks absolutely awful in git diff, apologies for that

  • The only change is the online key keyid changing and as a result that key moving
    a little in the sorted keys object. No key content changes here.
    • old: "7247f0dbad85b147e1863bade761243cc785dcb7aa410e7105dd3d2b61a36d2c"
    • new: "0c87432c3bf09fd99189fdc32fa5eaedf4e4a5fac7bab73fa04a2e0fc64af6f5"
  • Unfortunately the way Git shows this is a disaster
  • I have a small script that you can run on main branch (to see current situtation)
    and on the sign/root-v12 branch (to see situation in signing event) if that helps:
    https://gist.github.com/jku/4379186fd4ffb2a19798734c83deb695.

@jku
Copy link
Member

jku commented Feb 5, 2025

oops we needed to upgrade tuf-on-ci first

@jku jku closed this Feb 5, 2025
@jku jku changed the title Signing event: sign/root-v12 Canceled Signing event Feb 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants